Module: PuppetX::Consul::HTTPClient

Defined in:
lib/puppet_x/consul/http_client.rb

Constant Summary collapse

TLS_PARAMETERS =
%i[ca_file ca_path client_cert client_key].freeze

Class Method Summary collapse

Class Method Details

.build(uri, options = {}) ⇒ Object



13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
# File 'lib/puppet_x/consul/http_client.rb', line 13

def self.build(uri, options = {})
  http = Net::HTTP.new(uri.host, uri.port)
  return http unless uri.is_a?(URI::HTTPS)

  http.use_ssl = true
  http.verify_mode = OpenSSL::SSL::VERIFY_PEER
  http.verify_hostname = true
  http.ca_file = options[:ca_file] if options[:ca_file]
  http.ca_path = options[:ca_path] if options[:ca_path]

  if options[:client_cert] || options[:client_key]
    raise Puppet::Error, 'Consul client_cert and client_key must be supplied together' unless options[:client_cert] && options[:client_key]

    # PEM bundles contain the leaf certificate followed by its intermediate CAs.
    certificates = File.read(options[:client_cert]).scan(%r{-----BEGIN CERTIFICATE-----.*?-----END CERTIFICATE-----}m)
    raise Puppet::Error, 'Consul client_cert does not contain a PEM certificate' if certificates.empty?

    http.cert = OpenSSL::X509::Certificate.new(certificates.shift)
    http.extra_chain_cert = certificates.map { |pem| OpenSSL::X509::Certificate.new(pem) }
    http.key = OpenSSL::PKey.read(File.read(options[:client_key]), '')
    raise Puppet::Error, 'Consul client_key does not match client_cert' unless http.cert.check_private_key(http.key)
  end

  http
end

.tls_options(resource) ⇒ Object



9
10
11
# File 'lib/puppet_x/consul/http_client.rb', line 9

def self.tls_options(resource)
  TLS_PARAMETERS.to_h { |parameter| [parameter, resource[parameter]] }
end